Re: [PATCH wireless v4 3/3] wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
From: Jeff Johnson
Date: Mon Jul 13 2026 - 10:26:19 EST
On Thu, 25 Jun 2026 23:29:07 +0000, Tristan Madani wrote:
> The firmware-controlled num_msg field (u8, 0-255) drives the loop in
> ath6kl_wmi_tx_complete_event_rx() without validation against the buffer
> length. This allows out-of-bounds reads of up to 1020 bytes past the
> WMI event buffer when the firmware sends an inflated num_msg.
>
> Add a check that the buffer is large enough to hold the fixed struct
> and the num_msg variable-length entries.
>
> [...]
Applied, thanks!
[3/3] wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
commit: 3a21c89215cc18f1a97c5e5bfd1da6d4f3d44495
Best regards,
--
Jeff Johnson <jeff.johnson@xxxxxxxxxxxxxxxx>